CVE-2026-98320 PUBLISHED

netfilter: flowtable: hold reference on ct until flow is released

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: hold reference on ct until flow is released

nf_ct_put() releases the ct->ext area inmediately, the rcu typesafe semantics also allow to refer to the wrong conntrack from the flowtable datapath. Hold reference on ct until flow is released after rcu grace period.

Add rcu_barrier() on module exit path, to ensure pending flow entries are release before module goes away.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 0ff90b6c20340e57616a51ae1a1bf18156d6638a to 93ff1594be1aad4da364462dd8db050ebcfda2de (excl.)
  • affected from 0ff90b6c20340e57616a51ae1a1bf18156d6638a to eed6997e8dc40593a539fcc722e7ed51b18db86c (excl.)
  • affected from 0ff90b6c20340e57616a51ae1a1bf18156d6638a to 61c6688be282277c6e91ab286a7acd0ae8681ac6 (excl.)
  • affected from 0ff90b6c20340e57616a51ae1a1bf18156d6638a to a43cd2b67b91e943273c913237a7a88c50cdcfbc (excl.)
  • affected from 0ff90b6c20340e57616a51ae1a1bf18156d6638a to 8274cdc5f9c57e17ed77fc4ba76212536c840f25 (excl.)
  • affected from 0ff90b6c20340e57616a51ae1a1bf18156d6638a to 12c1ac230f4ca16e0017b62a963ab75e0b48074f (excl.)
  • affected from 0ff90b6c20340e57616a51ae1a1bf18156d6638a to d9e6175a3ee48209ee65f294fc567b4e16b29b74 (excl.)
  • affected from 0ff90b6c20340e57616a51ae1a1bf18156d6638a to e75a9fa1d44bcbd66ea02e8781bcca6ea4076e0d (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 4.16 is affected
  • unaffected from 0 to 4.16 (excl.)
  • unaffected from 5.10.271 to 5.10.* (incl.)
  • unaffected from 5.15.222 to 5.15.* (incl.)
  • unaffected from 6.1.189 to 6.1.* (incl.)
  • unaffected from 6.6.158 to 6.6.* (incl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References